We protect the CRM credentials and contact data of sales teams worldwide. Security is built into every layer of our platform.
Authenticated encryption
EU, UK & CCPA
Modern Chrome security
HSTS with preload
Your most sensitive data is protected with industry-standard encryption at every stage.
All CRM API keys and OAuth tokens are encrypted with AES-256-GCM authenticated encryption before storage. Credentials are never stored in plaintext. GCM mode provides both confidentiality and integrity verification.
All connections use TLS 1.2+ with auto-provisioned certificates. We enforce HSTS with preload to prevent protocol downgrade attacks. All API and web traffic requires HTTPS.
User passwords are hashed with bcrypt. We enforce minimum password complexity requirements and never store or log plaintext passwords.
All payment processing is handled by Stripe (PCI DSS Level 1 certified). We never see, store, or process credit card numbers. Webhook signatures are cryptographically verified.
Multiple layers of protection guard access to your account and data.
Built with defence-in-depth principles across every layer of the stack.
All database queries use parameterised prepared statements. No user input is ever concatenated into SQL.
A strict CSP is enforced across all routes, blocking inline scripts and restricting resource loading to trusted domains.
Built on Manifest V3 with the minimum required permissions. UI is fully isolated from host pages.
Generic error messages are returned to clients. Stack traces and internal details are never exposed to end users.
HSTS preload, X-Frame-Options DENY, X-Content-Type-Options nosniff, strict Referrer-Policy, and Permissions-Policy enforced.
Passwords and CRM credentials are stripped from all API responses before transmission. Sensitive values are never logged.
We comply with major data protection regulations worldwide.
| Data Category | Retention Period |
|---|---|
| Account data | Duration of account + 6 months |
| Enrichment cache | 30 days |
| Operation logs | 12 months |
| Inactive CRM credentials | Auto-deleted after 90 days of inactivity |
We use a limited number of trusted third-party services to provide our platform.
| Service | Purpose | Data Processed | Location |
|---|---|---|---|
| DigitalOcean | Infrastructure hosting | All application data | US |
| Stripe | Payment processing | Billing data | US (PCI DSS) |
| Apollo.io | Contact enrichment | Professional contact data | US |
| SalesQL | Contact enrichment | Professional contact data | EU |
| Prospeo | Contact enrichment | Professional contact data | EU |
| Bouncer | Email verification | Email addresses | EU |
| Authentication (OAuth) | Email, name | US | |
| PostHog | Product analytics | Usage events (no PII) | EU |
| Fathom | Website analytics | None (cookieless) | EU |
| MailerSend | Transactional email | Name, email | EU |
| MailerLite | Email marketing | Name, email | EU |
Reliable infrastructure with automated recovery and zero-downtime deployments.
Our primary infrastructure is hosted in the United States. For transfers of personal data from the EU/EEA to the US, we rely on the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) as additional safeguards.
Sellframe Ltd. is registered in Scotland, UK. We comply with both EU GDPR and UK GDPR requirements for international data transfers.
We are transparent about our security posture and happy to work with your team.
We respond to SIG Lite, CAIQ, and custom security questionnaires. We implement the technical controls required by SOC 2 and ISO 27001 frameworks.
We are happy to review and sign your DPA to formalise our data handling obligations and meet your compliance requirements.
We welcome responsible disclosure. If you discover a security issue, please reach out to us directly and we will respond promptly.
For security inquiries, vulnerability reports, or to request a security questionnaire response:
[email protected] →Last updated: 24th February 2026